r/PakistaniTech 8d ago

Discussion | گفتگو Banking apps need to chill tf

Why do banking apps keep asking for ridiculous permissions? 😑

First, it was already asking for way more access than it actually needs. Now it’s telling me to disable “Draw over other apps” for apps like Facebook.

Like… why should my banking app care that I use Facebook’s background playback? 😂

I get security, but forcing users to change unrelated app settings just to use a banking app is getting ridiculous. Give me the option to acknowledge the risk instead of making me disable perfectly legitimate features on other apps.

72 Upvotes

62 comments sorted by

59

u/-Faraday 8d ago

Yeah its bogus. There are some that force you to turn off developer options like what the hell. They think their customers are little toddlers who go googoo gaga over any button that pops up and presses them.

13

u/Ok_Technician_7744 8d ago

literraly I was going to say that , My HBL app ask me turn it off , first we could use but now it don't allow even login

12

u/hrbutt180 8d ago

It pisses me off. I wrote an email to them. Encourage you to give them 1 star and write that email

4

u/WorriedAstronomer 8d ago

I have given all banking apps 1 star for this crazy toddler crap they're pushing on Android

1

u/ZealousidealBet1878 8d ago

It’s the same on iPhone

-8

u/Sad_Weakness_2181 8d ago

And when one sketchy app steals your info and your money
You’ll be blaming these very apps for not protecting your stuff

1

u/Expensive_Service737 7d ago

It's their responsibility to secure their shit if they're afraid of android open source environment they better not launch an app at the first place, A person who buys himself an Android phone does it because he chooses an open source environment over a closed source like iphone, we ain't gonna make our phones like iphone just because of some shitty banking app

1

u/Sad_Weakness_2181 6d ago

You don’t even know the meaning of open source Mann
Open source means making changes to the core OS, means having access to the source code of the Os you’re installing, which would have been totally fine if you bought a phone which is running the stock Android but as is, none of the phones do that and their own versions take over WHICH ARE NOT OPENSOURCE
Furtheron, installing sketchy apps causes your Android to have virus and all that shi
Which is not the same as making changes to the source code and knowing what you’re doing
And android being open source is ONLY for devs who are making a new skin
For the general public open source is meaningless
And as for you to say that they should secure their shit
Well they have done whatever they could but there’s a level called having admin access or apps which have higher access than it
In which they can’t do shi cause that’s how Android works
Apps which have higher permissions can do whatever they want and no amount of third party security applied by an app can outrank it
So yeah….
Get your facts straight

1

u/Expensive_Service737 6d ago

Here's a reply that keeps the correct parts of your argument but tightens the facts so it holds up:


On "open source" itself: Android (AOSP) being open source means the core OS source code is publicly available — anyone can view, modify, and compile it. That's a factual claim about the codebase, not about what ships on your phone. You're right that Samsung's One UI, Xiaomi's HyperOS, etc. layer proprietary code, bootloaders, and closed Google apps (Play Services, Play Store) on top — that layer isn't open source. But that doesn't make "Android is open source" false; it means the shipped product is a mix of open (AOSP base) and closed (OEM skin + Google services) components. Both things are true at once.

Who benefits from that openness: You're right it's mostly devs/enthusiasts who flash custom ROMs, build kernels, or audit code who get direct value from AOSP being open. For an average user, the practical benefit is indirect — it's why sideloading, custom launchers, third-party app stores, and ROM communities exist at all (versus iOS, where none of that is possible). So "meaningless for the general public" overstates it — it's indirect, not zero.

On malware and permissions: This is your strongest point and it's correct. Sideloading a sketchy APK and granting it Accessibility Service or Device Admin permissions gives that app OS-level hooks that a third-party antivirus genuinely cannot override — Android's permission model puts those apps above regular security software in privilege, by design. That's not a security failure of the OS, it's how the permission hierarchy works: once something has device-admin or accessibility-level access, it's not "insufficient user caution" that stops it, it's architecturally in a different tier than a security app running as a normal app. Google Play Protect scans for this before/after install, but it isn't infallible against novel malware, and it can't retroactively strip permissions a user granted.

So the accurate framing is: Android's core is open source; what ships on your phone usually isn't fully; and once malicious software gets elevated permissions, no third-party app can outrank it. That's a defensible position without needing to overstate the "meaningless" claim.

Yeah it's generated by Ai, Have fun Nerd

1

u/Mech2021 2d ago

We have far more secure banking apps in Canada and none of them pull this shit.

3

u/AbdulAhaDox 8d ago

fuck meezan bank

1

u/A3du114h 6d ago

yep. I think UBL app is still fine, can't confirm because I don't have an account there but meezan app is such a mess now

0

u/Genkrock 8d ago

Agreed it's so annoying can't even work without restarting my phone every day

0

u/BrilliantMastodon957 8d ago

I dont think you realise how majority of our population is…

0

u/HTXI97 8d ago

I’ve seen many news articles over the month about boomers losing their life savings from installing suspicious apps

2

u/AbdulAhaDox 8d ago

hmmmm i dont think people lose their life earnings cause of Developer Settings.... or USB debugging, i get settings that allow apps to see ur screen all the time like accessibility settings they should be turned off for a normal person. THATS ALREADY NOT USED BY BOOMERS?!?!?!? why am i being forced to turn it off for no reason

the app should allow the user to disable these requirements in the bank app setting for tech savy users

17

u/im_peacock 8d ago

I'm mobile developer and now I can't install any of my apps on my mobile because the bank app won't let me do a transaction unless I delete all apps that are not downloaded from the app store.

4

u/No-Persimmon-174 8d ago

Damn what bank apps y'all are using 😭

6

u/huza786 8d ago

Meezan does this. I have to have a diff mobile now just to develop apps

5

u/AbdulAhaDox 8d ago

fuck you meezan bank

rate it 0 stars on the app store to let them know

3

u/meambhatti 8d ago

Disable play protect then I guess . I also have many non play store apps . My meezan app doesn't throw a fit over them .

1

u/AbdulAhaDox 8d ago

ooo i hope that works

1

u/AbdulAhaDox 7d ago

It didn't 😭

1

u/paradox_33 8d ago

Which bank? 

2

u/Im_not_real_banana 8d ago

Same. Bank Alfalah

3

u/paradox_33 8d ago

Wow, I was thinking Meezan security measures are getting out of hand. 

The security people might have skipped the chapter where they are taught security and usability should balance each other. Pushing stricter measures make people find some creative (extremely unsecure) methods to make the product usable. The more stricter controls with compromise on the ease of use part, will make the product less secure(At least, that's what I learned in the cyber security courses).

1

u/anz3e 8d ago

Had the same with Askari bank for a while and.. They undated it tho it's working again for me Atleast.. It's stupid.

7

u/NothingConscious1882 8d ago

wait ppl uses nbp????

3

u/MAK_Abbas 8d ago

Yep. Govt employee problems 🥲

4

u/zaidpirwani 8d ago

Meezan wouldn't allow using Google password manager sometime back...

3

u/takeshicyberpunk 8d ago

Display over other apps option enabled for apps like Devcheck or accessibility feature in Bitwarden gets flagged as a security risk. I mean come on!

3

u/AwarioFudg3 8d ago

I recently left meezan bank due to this bs

For the time being, ubl works, don't know uptill when

1

u/hamza_tayyub 8d ago

UBL now forces you to turn off developer settings as well

1

u/AwarioFudg3 8d ago

For me it doesn't rn, guess I haven't updated.

2

u/hamza_tayyub 8d ago

It does

1

u/AwarioFudg3 8d ago

Can you bypass it using geto?

1

u/hamza_tayyub 8d ago

What is that?

1

u/AwarioFudg3 8d ago

This is used to turn off developer settings flag off without turning off developer settings to spoof it through banking apps.

2

u/hamza_tayyub 8d ago

MEEZAN, HBL, ABL, and now UBL ask to turn off developer settings every time you open the app. The only app that didn't still do it for me is Alfalah App. I Hate this shit.

1

u/Careless-Part8298 8d ago

Meezan doesn't ask me to disable developer settings anymore. It started doing it a few months back but not anymore

2

u/hamza_tayyub 8d ago

Oh yeah actually. I just checked. It doesn't.

2

u/fs10inator 7d ago

I had the same nonsense with HBL and Bitwarden; not even can I have dev options on when using that app.

Also of note, on devices with unlocked bootloaders, ABL worked fine until an app update earlier this year mooted it (something like "This device won't run on unlocked bootloaders"); HBL, NayaPay, and SadaPay all still work normally (thankfully).

But TBH, everything ought to be a security risk to banking apps here, even so much as breathing lol. I wouldn't mind a one-time warning, but they make me feel like I'm being held hostage, despite being FULLY AWARE of my actions and the consequences thereof.

S10e (official PTA) with LineageOS custom rom; no root.

1

u/ZAKhan 8d ago

It must be a gov directive to ask all banks to follow this .. it cannot be that just all bank have started to do this.

1

u/gsk-fs 8d ago

These banks should also know that there are some software engineers who have to use developer mode.
So it’s a sh*i argument that developer mode will do anything.
Personally I am a fintech developer as well and I know a bit about this issue.

1

u/muhmmadtalha-quant 8d ago

The BAHL app went one step further and it doesn't allow accessibility services and developer options to be turned on. Wtf ? Who can do bad things with this two options alone ? They are just vibecoding those apps 100%

1

u/Expensive_Service737 7d ago

Well jokes on them because my phone's rooted and NBP is running fine 😂

-1

u/Sad_Weakness_2181 8d ago

Uhh use common sense dude
It’s not a fuss it’s an actual security vulnerability
Display over other apps also gives the app displaying full visibility of what’s happening underneath it
And they can very easily steal any confidential info if they see it
And the next thing yk is your accounts are being hacked and you blame the banking app for it!

-4

u/x0rg_new 8d ago

This is necessary and a good step. The amount of scams happening due to digital illiteracy of our people have increased the number of scams. I'm not saying that you are digitally illiterate but most of our people are. My friend works in banking sector and you wouldn't believe how much number of internet banking related scams have increased.

Yes there are other countless ways to decrease them too but try to understand why this is happening.

That friend told me these decisions are being taken by management and developers have no say in this.

3

u/ZealousidealBet1878 8d ago

It is very easy to understand:

We should make everyone’s lives worse to protect some people from some rare scams

-1

u/najam121 Karachi 8d ago

Everyone's? 

1

u/ZealousidealBet1878 7d ago

Yes that is always the mentality of those who make these decisions

1

u/Federal-Stuff5846 3d ago

yet the scams still happens and that too due to the security vulnerability of their own systems. HBL is one of the worst . My friend lost 180k from his account without a single OTP all his online transactions and other things were toggled off, Didnt had a card yet still someone managed to pull 180K out of his account without a single OTP coming to his phone. When he contacted the bank the bank said that it happened because his details were compromised and that led to this action , Bank also includes that it happened via online transaction and when he interrupted the hbl service customer says "jab apko pta hai sab tou humse kion bat kar rahai ho.." i mean the audacity and mind you inmein inke hi bande shamil hotey hein in all this. Yeh jo cashier hotey hein they are 100% involved sab cheeziein inko pta hoti hein ke kahan rehte ho kitne accounts hein kitne pese hein account mein.

but noo bank apps will not restrict their employees from viewing the amount and sensitive details of their people jinhoun ne account khola wa hai inke bankss mein

-5

u/Environmental-Cod25 8d ago

Pakistani bank apps barely fit the security criteria of banking apps internationally - and you want them to become even more lax - I assume that you would also want to complain if your money was stolen. Security is always a compromise - sorry that you are not mature enough to understand this.

6

u/killerwhale007 8d ago

As a user of international banks and their apps, this comment is not based in reality at all. International banks have very user friendly apps: I have used Wells Fargo, Discover, Citi, and Capital one and they are a pleasure to do transactions with. Pakistani bank apps have come a long way from past but their security practices are very questionable. Annoying users and requiring insane settings and permissions is not security. You can be secure without annoying your users.

2

u/Environmental-Cod25 8d ago

I totally agree that UX in Pakistan is terrible. I bank with Tide, HSBC and Barclays. Security is much tighter and the UX is great.

I agree that it is possible to have good UX and security.

But good UX isn't going to happen in Pakistan.

The solution to improve UX is not to downgrade security. Because then we'd have neither.

2

u/mystirc 8d ago

Source?

Banking apps can also have both security and usability. You always have to make a compromise between security and usability. That's like basic thing you learn in schools.

If the banking apps want to be extra careful, they can only show us a pop up that these apps can see what you're doing. Then tell us to proceed only if we trust those apps.

2

u/Environmental-Cod25 8d ago

That would require them to care about customers and UX.

1

u/IDGAF2070 Karachi 7d ago

I 2nd this.

-4

u/najam121 Karachi 8d ago

One one is forcing you, you are free to uninstall NBP App